Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpoint. This manipulation causes missing authentication. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | sdcb chats Signed File Download Endpoint FileController.cs DownloadPublic missing authentication | |
| First Time appeared |
Sdcb
Sdcb chats |
|
| Weaknesses | CWE-287 CWE-306 |
|
| CPEs | cpe:2.3:a:sdcb:chats:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sdcb
Sdcb chats |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-31T20:00:10.019Z
Reserved: 2026-08-31T09:46:30.626Z
Link: CVE-2026-82906
No data.
Status : Received
Published: 2026-08-31T21:17:54.330
Modified: 2026-08-31T21:17:54.330
Link: CVE-2026-82906
No data.
OpenCVE Enrichment
No data.